Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base

CIS
linux/amd64
debian 13
Tags:

trixie, trixie-debian13

Index digest:

sha256:49fbbd8f45fb8526261265963f531f67390ff0ba49bdafd0fb813c2acd5c0531

Manifest digest:

sha256:2befbed7a36fd07838434de2c20140b5221e4b0f13e87d06024afd6954ef23fd

Size

12.61 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:aa62e0a6f4e165ecf9661dcc24e64f5d19a597aee1c77ca7d40aa7467e2785b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:544c98ad8e4002843fcab6d0a38bf85dda5c96a7be9d27c51192cef0375de99f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:5314bb7ede19473de4fbacb71f5c759515f2aaf8219038e5b5b417a5d330914c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:3226e407fe6a2bd0b8574b996462356365f215c65d34a173fc26dd7f9e4818c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:37036f9c5fabc3c52d704fbdfaa0504e2bd3f5b03bf47f1cf6f6abfb8b8bf6d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:94df7f7cb3c4aa2acbf4231330cbea7924aa9699c935afa2bb352197bdcd8b6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:64222efb09b23cb48fb93950be2ad042eaaa589aa085d04b25f0f9f021af8163
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:9c402a5bedaaaa592eb05eac67753e49b6291605bdf90ff9b525dc58cacf43bb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:eaf5ecd93081260db54fbe15f858c52d24d1c775dac14eddf222d779a41bf312
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:24955604c329a9742b03602c1f5c058528ec61e90270f9e882d6f89caf9272ba
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:a18f373d36d9c6b6a3a943b91371ccb91f4fbded6befefb89baf9f9f67e5d361
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:1c9a01d6eefb3dbeff6d8c1b993621358b4de1ad620a108165e10036168e92ce
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:b69ed2a69b2f50cdc70f46f5c3ad6d055ae8033ba1032c62bb30c490cad35292
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:2c39f25c5506239858ad6f6e4f75c9858559b14a0194757ef030c116c21957d7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:9257917f6137cb9a9bad072d93ef7987c3395132f8c86161064cf768efb8f357